Show filters
488 Total Results
Displaying 371-380 of 488
Sort by:
Attacker Value
Unknown

CVE-2008-3092

Disclosure Date: July 09, 2008 (last updated October 04, 2023)
SQL injection vulnerability in the Taxonomy Autotagger module 5.x before 5.x-1.8 for Drupal allows remote authenticated users, with create or edit post permissions, to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown

CVE-2008-3096

Disclosure Date: July 09, 2008 (last updated October 04, 2023)
The Outline Designer module 5.x before 5.x-1.4 for Drupal changes each content reader's authentication level to match that of the content author, which might allow remote attackers to gain privileges.
0
Attacker Value
Unknown

CVE-2008-3000

Disclosure Date: July 03, 2008 (last updated October 04, 2023)
The Aggregation module 5.x before 5.x-4.4 for Drupal, when node access modules are used, does not properly implement access control, which allows remote attackers to bypass intended restrictions.
0
Attacker Value
Unknown

CVE-2008-2998

Disclosure Date: July 03, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the Aggregation module 5.x before 5.x-4.4 for Drupal allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2008-3001

Disclosure Date: July 03, 2008 (last updated October 04, 2023)
The Aggregation module 5.x before 5.x-4.4 for Drupal allows remote attackers to upload files with arbitrary extensions, and possibly execute arbitrary code, via a crafted feed that allows upload of files with arbitrary extensions.
0
Attacker Value
Unknown

CVE-2008-2999

Disclosure Date: July 03, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in the Aggregation module 5.x before 5.x-4.4 for Drupal allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown

CVE-2008-2850

Disclosure Date: June 25, 2008 (last updated October 04, 2023)
SQL injection vulnerability in the TrailScout module 5.x before 5.x-1.4 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified cookies, related to improper use of the Drupal database API.
0
Attacker Value
Unknown

CVE-2008-2849

Disclosure Date: June 25, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the TrailScout module 5.x before 5.x-1.4 for Drupal allows remote authenticated users, with create post permissions, to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2008-2772

Disclosure Date: June 18, 2008 (last updated October 04, 2023)
The Magic Tabs module 5.x before 5.x-1.1 for Drupal allows remote attackers to execute arbitrary PHP code via unspecified URL arguments, possibly related to a missing "whitelist of callbacks."
0
Attacker Value
Unknown

CVE-2008-2773

Disclosure Date: June 18, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Taxonomy Image module 5.x before 5.x-1.3 and 6.x before 6.x-1.3, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0